Privacy Policy
This policy describes the Clawsum operator platform and the Clawsum Admin Google OAuth client. It is written for Google app verification and for people who connect a Gmail mailbox. It is not legal advice.
1. Who we are
Clawsum is a self-hosted CEO operating system (conversation face, task governance, and scoped agents). The public site is clawsum.com. Contact: clawsums@gmail.com.
2. What this app accesses (Google)
The Clawsum Admin OAuth client requests only
https://www.googleapis.com/auth/gmail.readonly.
It can read mail the signed-in Google account can already see. It cannot send, delete,
or change labels.
On the reference Clawsum instance the authorized mailbox is clawsums@gmail.com (the operator inbox). Connecting a different Google account would authorize that account’s mail only — never someone else’s.
3. How we use Gmail data
We use readonly mail solely to operate the instance that completed OAuth:
- Archive messages into our self-hosted Postgres database (
ops.emails) - Triage, daily briefs, reminders, and Paperclip task suggestions for the operator
- Show inbox heat in the Boss / Hermes UI
We do not use Gmail data for advertising, credit decisions, or sale to data brokers.
Clawsum’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. What else we collect
- Enrollment form fields on /offer/ (name, email, phone if given, plan, notes) so we can send a written order
- Operational logs on the self-hosted stack (approvals, tasks, health metrics)
- Standard web logs on the public site (IP, user agent) for security and uptime
5. Storage and sharing
Mail and ops data live on infrastructure we operate (currently a private VPS and Postgres). They are not stored in Google except in the source mailbox. We do not sell personal data. We share it only with processors we use to run the instance (for example a VPS host), if required by law, or with people the operator explicitly invites into that instance.
6. Retention and deletion
Archived mail remains until the operator deletes it from Clawsum or we delete the instance. OAuth tokens stay in the instance environment until rotated or revoked. You can revoke Clawsum Admin at any time: Google Account → Third-party access. After revoke, new Gmail API calls fail; ask us to wipe stored copies at clawsums@gmail.com.
7. Children
Clawsum is not directed at children under 13. We do not knowingly collect their data.
8. Changes
We will update this page and the effective date if the practice changes in a material way.
9. Contact
Privacy questions: clawsums@gmail.com
Related: Terms of Service ·
Founding commercial summary